fix: correct 7 bugs found in security audit

Critical:
- crypto.rs (server): use BTreeMap for canonical JSON so key order
  matches JS client's JSON.stringify sort — sig verification was always
  failing silently
- heartbeat.js: capture sentSalt before rotating to next_salt so both
  sides compute next_chain_hash with the same salt — chain was broken
  after the first heartbeat

High:
- trust.rs: avg_speed = total_dist / total_time_ms (px/ms), not
  distance/event_count — legitimate users were always rejected
- ratelimit.rs: add evict_stale() to drain expired entries and prevent
  unbounded HashMap memory growth
- cleanup.rs: call rl.evict_stale() from the periodic cleanup loop

Medium:
- vm.rs: op 0x08 (NOT) is unary — split from binary-op arm so depth
  is not decremented incorrectly
- wasm/crypto.rs: replace unwrap() panics in sign_message /
  get_public_key with unwrap_or_default(); add JS-side guard

Low:
- shared/Cargo.toml, wasm/Cargo.toml: remove leftover add-this comments
- Dockerfile: rust:1.88-bookworm -> rust:1.87-bookworm (1.88 non-existent)
This commit is contained in:
thakares committed 2026-05-08 14:27:41 +05:30
1 parent 3f779a5295
commit b75d586b86
10 files changed
+103 -43

No files matched your search

+10 -5
View File
@@ -5,22 +5,27 @@ pub fn validate_mouse(data: &EntropyData) -> Result<(), Box<dyn std::error::Erro
if events.len() < 3 {
return Err("few events".into());
}
let mut total_dist = 0.0;
let mut total_dist = 0.0f64;
let mut pauses = 0u32;
for i in 1..events.len() {
let p = &events[i-1];
let p = &events[i - 1];
let c = &events[i];
let dx = c.x - p.x;
let dy = c.y - p.y;
let dt = (c.timestamp_ms - p.timestamp_ms).max(1.0);
let dist = (dx*dx + dy*dy).sqrt();
let dist = (dx * dx + dy * dy).sqrt();
total_dist += dist;
if dist < 0.2 && dt > 50.0 { pauses += 1; }
if dist < 0.2 && dt > 50.0 {
pauses += 1;
}
}
if total_dist < shared::constants::MIN_MOUSE_TOTAL_DIST {
return Err("insufficient distance".into());
}
let avg_speed = total_dist / events.len() as f64;
// Speed in px/ms: total distance over elapsed wall-clock time of the event window.
let total_time_ms =
(events.last().unwrap().timestamp_ms - events[0].timestamp_ms).max(1.0);
let avg_speed = total_dist / total_time_ms;
if avg_speed > shared::constants::MAX_MOUSE_AVG_SPEED {
return Err("speed too high".into());
}